Yearn Finance Faces New Security Breach in yETH Liquidity Pool

Beginner
Quick Reads
Last Updated 2026-03-27 07:57:27
Reading Time: 1m
Yearn Finance's yETH pool was recently hit by a highly sophisticated attack. The attacker used manipulated minting events to rapidly withdraw the majority of LST assets from the pool. This resulted in millions of dollars in losses. While Yearn's primary Vault products remained unaffected, this incident highlights the ongoing security challenges DeFi protocols face in cross-contract interactions, minting mechanisms, and asset pool governance.

Major Security Risk Hits Yearn Finance yETH Pool

Yearn Finance, the decentralized yield protocol, has once again faced a security incident. The yETH liquidity pool recently experienced irregular trading activity, with a substantial volume of Liquid Staking Tokens (LSTs) withdrawn in a short span. As the primary pool aggregating leading LSTs, the yETH pool is a cornerstone of the Yearn protocol. This incident is a significant concern for the market.

Attack Method: Forged Minting and Instant Pool Drain

On-chain data shows that the attacker deployed a series of custom contracts to mint an unlimited supply of yETH tokens in a single transaction. Using these artificially generated tokens, they exchanged for all LST assets in the pool, resulting in the pool being emptied within seconds. The losses are estimated at several million US dollars.

Following the attack, approximately 1,000 ETH (about $3 million) was quickly transferred into Tornado Cash, complicating efforts to trace the funds. Multiple attack contracts self-destructed after execution, highlighting the attack’s meticulous planning and technical sophistication.

Loss Estimates Await Official Confirmation

Prior to the incident, the yETH pool held roughly $11 million in assets. However, the actual losses require confirmation from Yearn Finance and blockchain security teams, as some ETH may have been consumed or become untraceable during the exploit.

On-chain analyst Togbe was the first to detect the breach, identifying anomalies while tracking large fund movements and bringing the attack to light.

Official Response and Historical Context


(Source: yearnfi)

Yearn Finance announced on X that it is actively investigating the incident. The team emphasized that V2 and V3 Vaults remain unaffected. The protocol has previously faced several security and technical challenges:

  • 2021: yDAI Vault vulnerability resulted in losses of approximately $11 million
  • 2022: Founder Andre Cronje announced his departure from the project
  • Late 2023: A script error reduced treasury assets by 63%, though user funds were not impacted

As of now, Yearn’s team has not released further details from its investigation. The market continues to await additional updates.

To learn more about Web3, sign up here: https://www.gate.com/

Summary

This incident demonstrates that even long-standing DeFi protocols with robust communities and audit histories remain vulnerable to flaws in contract logic, cross-contract interactions, and governance design. Yearn Finance needs to focus not only on fixing vulnerabilities but also on restoring market trust. The broader DeFi ecosystem is reminded that security audits, monitoring systems, and ongoing maintenance are critical for long-term stability. While innovation drives DeFi forward, striking the right balance between speed and security will ultimately determine the sector’s longevity and success.

Author: Allen
Disclaimer
* The information is not intended to be and does not constitute financial advice or any other recommendation of any sort offered or endorsed by Gate.
* This article may not be reproduced, transmitted or copied without referencing Gate. Contravention is an infringement of Copyright Act and may be subject to legal action.

Related Articles

What is Fartcoin? All You Need to Know About FARTCOIN
Intermediate

What is Fartcoin? All You Need to Know About FARTCOIN

Fartcoin (FARTCOIN) is a representative meme coin within the Solana ecosystem based on an AI-driven narrative. Its core concept originated from an experiment aimed at exploring the "boundaries between AI Agents and humor." More than just a digital asset with social attributes, the project deeply couples absurd humor culture with on-chain financial logic by integrating autonomous AI interaction models.
2026-04-04 22:01:19
Gold Price Forecast for the Next Five Years: 2026–2030 Trend Outlook and Investment Implications, Could It Reach $6,000?
Beginner

Gold Price Forecast for the Next Five Years: 2026–2030 Trend Outlook and Investment Implications, Could It Reach $6,000?

Analyze current gold price trends alongside authoritative five-year forecasts, integrating an evaluation of market risks and opportunities. This gives investors insight into the potential trajectory of gold prices and the main drivers expected to shape the market over the next five years.
2026-03-25 18:13:30
Aster vs Hyperliquid: Which Perp DEX Will Prevail?
Beginner

Aster vs Hyperliquid: Which Perp DEX Will Prevail?

Aster and Hyperliquid are the two representative protocols of the "purpose-built L1 path" within the current decentralized perpetual exchange (Perp DEX) sector. As a pioneer in the field, Hyperliquid has built a deep liquidity moat through its highly mature order book architecture and strong community consensus. Conversely, Aster, as a rising challenger, seeks to leapfrog the competition in high-performance trading through more aggressive multi-chain aggregation logic, private transaction modules, and an underlying execution environment optimized for 2026 market demands.
2026-03-24 11:58:33
AI-Native Settlement Layers: How United Stables Is Building the Next Financial Rail
Beginner

AI-Native Settlement Layers: How United Stables Is Building the Next Financial Rail

Stablecoins were originally designed as dollar substitutes within exchanges, primarily used for asset pricing and trade settlement. As on-chain financial ecosystems have matured, their role has expanded beyond simple payments to include collateral assets, cross-chain liquidity mediums, and unified settlement units. In particular, as AI systems and automated agents begin to participate directly in economic activity, demand has risen sharply for programmable value units capable of instant settlement. This shift is pushing stablecoins toward the role of foundational financial infrastructure.
2026-03-25 03:16:17
Aerodrome Tokenomics: How ve(3,3) Powers Base's Most Profitable DEX
Beginner

Aerodrome Tokenomics: How ve(3,3) Powers Base's Most Profitable DEX

AERO is the native token of Aerodrome Finance, a core decentralized exchange and liquidity protocol in the Base ecosystem. It is primarily used for liquidity incentives and ecosystem operations. veAERO is a governance NFT that users receive by locking AERO, representing both voting power and the right to share protocol revenue. Through a dual track structure of AERO as a utility token and veAERO as a governance credential, Aerodrome separates liquidity usage value from long term governance power, allowing participants to act as liquidity providers, governance decision makers, and revenue sharers within the same system.
2026-03-25 06:40:31
Hybrid Collateral Stablecoins: Inside United Stables' Stability and Yield Architecture
Beginner

Hybrid Collateral Stablecoins: Inside United Stables' Stability and Yield Architecture

In the early stages of the crypto market, traditional stablecoins mainly relied on single-reserve or single-collateral models. Their primary focus was price stability and payment convenience, which allowed them to become foundational tools for on-chain trading and capital flows. As the market has entered a more mature financial phase, however, this structure has begun to reveal limitations, including high concentration risk and the difficulty of balancing liquidity with yield. These constraints have driven the evolution toward multi-layer collateral and portfolio-based designs, such as the dual-layer hybrid collateral architecture proposed by United Stables, which seeks to redefine the underlying logic of stable assets.
2026-03-25 03:17:39